CVE-2026-32996 is a local privilege-escalation vulnerability in Veeam Agent for Microsoft Windows 13.0.1.2067 and earlier version 13 builds. The Veeam Endpoint Backup service associates an elevated administrator identity with a client-controlled session UID over its local gRPC interface without securely binding that UID to the requesting user or connection. Elevated session UIDs are recorded in a log readable by standard local users. A low-privileged local user can recover and reuse a valid UID to cause the service to execute commands as NT AUTHORITY\SYSTEM.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This four-file C#/.NET 10 proof-of-concept targets CVE-2026-32996 in Veeam Endpoint Backup (Veeam Agent for Microsoft Windows) versions 13.0.2.1102 and earlier. Program.cs is the sole executable entry point; the solution and project files build it as a console application and reference locally installed Veeam assemblies, while README.md documents usage and affected versions. The program reads the Veeam service log in reverse order to collect logged elevated-client GUIDs, tests each GUID by adding it as a caller-sessionId gRPC header and calling HasAdminRights over Veeam's local ServiceConnection named pipe, then uses a valid GUID to access IEndpointManagementService. It sets the DismPath option to cmd.exe and calls RunDismCommand with an attacker-controlled command, providing local privileged command execution. Although the README describes remote RCE, the supplied source itself communicates only with localhost via a local named pipe and implements a local escalation technique.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Vulnérabilité locale d’élévation de privilèges dans Veeam Agent for Microsoft Windows, signalée comme activement exploitée. Une version corrigée est disponible.
A critical local privilege-escalation vulnerability in the Veeam Endpoint Backup service in Veeam Agent for Microsoft Windows. A low-privileged local user can recover a valid elevated session UID from a readable Veeam log file and reuse it through the local gRPC named-pipe interface to execute commands as NT AUTHORITY\SYSTEM.
A critical local privilege-escalation vulnerability in Veeam Agent for Microsoft Windows. A local attacker can read a valid elevated session UID from a world-readable Veeam log and abuse the service's improperly bound gRPC session handling to execute commands as SYSTEM.
A local privilege-escalation flaw in Veeam Agent for Microsoft Windows v13.0.1.2067 and earlier v13 builds. The Veeam Endpoint Backup service improperly binds cached elevated administrator sessions to client-controlled session UIDs, allowing a low-privileged local user to obtain a UID from a readable log and execute commands as SYSTEM.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.